CVE-2022-41333 is an uncontrolled resource consumption vulnerability affecting FortiRecorder firmware versions 6.4.3 and below, and 6.0.11 and below. This flaw allows an unauthenticated attacker to cause a denial of service by sending crafted GET requests to the login authentication mechanism. With a CVSS score of 7.5 (High), the vulnerability is easily exploitable over the network with no user interaction, leading to high availability impact. While not currently on the KEV catalog or showing significant community discussion or media coverage, a public exploit (EDB-51326) exists, indicating its potential for exploitation.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
>= 6.0.0, <= 6.0.11CPE matchmatch criteria | cpe:2.3:o:fortinet:fortirecorder_firmware:*:*:*:*:*:*:*:* | ||
>= 6.4.0, <= 6.4.3CPE matchmatch criteria | cpe:2.3:o:fortinet:fortirecorder_firmware:*:*:*:*:*:*:*:* | ||
>= 6.0.0, <= 6.0.11CPE match | cpe:2.3:a:fortinet:fortirecorder:*:*:*:*:*:*:*:* | ||
>= 6.4.0, <= 6.4.3CPE match | cpe:2.3:a:fortinet:fortirecorder:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.